Job Requirements
Quantico, VA
Secret Polygraph Unspecified
Mid Level Career (5+ yrs experience)
Salary not specified
Join Premium to unlock estimated salaries
Job Description
RMF/ATO Analyst
Full Time | Quantico, VA | Secret Clearance Required
SteelGate is seeking an experienced Risk Management Framework (RMF) / Authorization to Operate (ATO) Analyst to support cybersecurity authorization, compliance, documentation, and continuous monitoring activities for the U.S. Government.
The RMF/ATO Analyst will support the development, maintenance, assessment, and management of RMF documentation and authorization packages for the customer’s information systems. The position will work closely with Government cybersecurity personnel, ISSOs/ISSMs, system owners, and A3T's cybersecurity and engineering teams to maintain system authorization and compliance throughout the system lifecycle.
Key Responsibilities
• Support implementation and execution of the DoD Risk Management Framework (RMF) for assigned information systems.
• Develop, maintain, review, and update RMF and cybersecurity authorization documentation.
• Support preparation and maintenance of ATO packages throughout the authorization lifecycle.
• Maintain system authorization information and cybersecurity artifacts within eMASS.
• Support development, review, and maintenance of system security documentation and RMF artifacts.
• Coordinate security-control implementation and documentation with system owners, ISSOs/ISSMs, Systems Engineers, Network Engineers, Cloud Engineers, and Systems Administrators.
• Collect, review, organize, and validate technical evidence supporting security-control implementation and assessment.
• Track security-control deficiencies and support development and maintenance of Plans of Action and Milestones (POA&Ms).
• Monitor POA&M corrective actions and coordinate with responsible technical personnel to obtain evidence of remediation and closure.
• Support RMF control assessments, security reviews, validation activities, and authorization decisions.
• Review DISA STIG, vulnerability, configuration, and cybersecurity assessment results for inclusion in authorization documentation.
• Assist technical teams with interpreting RMF documentation and evidence requirements.
• Support continuous monitoring activities to maintain system authorization and cybersecurity compliance.
• Evaluate proposed system changes to determine potential impacts to authorization boundaries, security controls, and existing ATOs.
• Maintain accurate system inventories, authorization boundaries, architecture information, control documentation, and supporting artifacts.
• Coordinate authorization activities with Government cybersecurity personnel and other applicable USMC/DoD stakeholders.
• Track RMF milestones, deliverables, assessment findings, authorization expiration dates, and other compliance requirements.
• Support recurring cybersecurity reviews and provide RMF/ATO status information for program and Government briefings.
• Assist with development and delivery of RMF-related training and guidance to technical and program personnel.
• Support reauthorization activities, system modifications, technology refreshes, migrations, and system decommissioning as required.
Minimum Experience:
• Must have 5–8+ years of cybersecurity, information assurance, RMF, ATO, or security-compliance experience.
• Must have an active DoD Secret security clearance.
• Must satisfy applicable DoD 8140/DCWF requirements for Work Role 722 at the Advanced proficiency level.
• Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or related discipline.
• Hands-on experience supporting the DoD Risk Management Framework and system authorization processes.
• Experience developing and maintaining RMF/ATO documentation and supporting artifacts.
• Demonstrated experience using eMASS.
• Experience with security-control implementation, assessment, documentation, and evidence collection.
• Experience developing and managing POA&Ms and tracking cybersecurity findings through remediation.
• Working knowledge of DoD cybersecurity policies and authorization processes.
• Knowledge of NIST security controls, DISA STIGs, vulnerability-management processes, and continuous monitoring.
• Ability to interpret technical cybersecurity findings and translate them into appropriate RMF documentation.
• Experience coordinating with ISSOs, ISSMs, system owners, engineers, administrators, and Government cybersecurity personnel.
• Strong analytical, organizational, documentation, and communication skills.
Preferred Qualifications:
• CISSP, CAP/CGRC, SecurityX/CASP+, Security+, or other certification appropriate to the assigned DCWF work role.
• Extensive experience with eMASS and DoD RMF authorization packages.
• Experience supporting USMC or Department of the Navy RMF processes.
• Experience with NIST SP 800-53 security controls.
• Familiarity with ACAS/Tenable vulnerability results and DISA STIG compliance.
• Experience supporting cloud or hybrid environments, including Microsoft Azure.
• Experience with Microsoft 365 security/compliance environments.
• Previous USMC, Navy, DISA, or other DoD RMF/ATO experience.
Job Types: Full-Time
Salary: Based on experience
Schedule: Monday-Friday
Benefits:
• 401(k) matching
• Dental insurance
• Health insurance
• Paid time off
• Professional development assistance
• Vision insurance
STEELGATE LLC is a Service-Disabled, Veteran-Owned Small Business (SDVOSB) that prides itself in hiring top-level Subject Matter Experts (SME’s) proven to exceed deliverable expectations. STEELGATE LLC is focused on solving the hard problems facing our government and commercial clients. Our success lies in blending together relevant domain/functional knowledge with deep expertise in Information Technology, Cybersecurity, Defensive Cyber Operations, cloud-based DevSecOps, Data Analytics & AI, Acquisition and Acquisition Management, and more. STEELGATE LLC has a positive, inclusive workplace environment where all team members and partners work towards mutual success. We have established a reliable reach-back program whereas all SMEs are available to support, advise and directly complete mission deliverables when necessary. STEELGATE LLC has a worldwide reputation as a valued and trustworthy partner. Our can-do attitude and willingness to support any mission requirement sets us apart from other small business organizations. Find out more about STEELGATE LLC @ www.steelgatellc.com.
We are an equal opportunity employer, and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, protected veteran status, or any other characteristic protected by law.
Full Time | Quantico, VA | Secret Clearance Required
SteelGate is seeking an experienced Risk Management Framework (RMF) / Authorization to Operate (ATO) Analyst to support cybersecurity authorization, compliance, documentation, and continuous monitoring activities for the U.S. Government.
The RMF/ATO Analyst will support the development, maintenance, assessment, and management of RMF documentation and authorization packages for the customer’s information systems. The position will work closely with Government cybersecurity personnel, ISSOs/ISSMs, system owners, and A3T's cybersecurity and engineering teams to maintain system authorization and compliance throughout the system lifecycle.
Key Responsibilities
• Support implementation and execution of the DoD Risk Management Framework (RMF) for assigned information systems.
• Develop, maintain, review, and update RMF and cybersecurity authorization documentation.
• Support preparation and maintenance of ATO packages throughout the authorization lifecycle.
• Maintain system authorization information and cybersecurity artifacts within eMASS.
• Support development, review, and maintenance of system security documentation and RMF artifacts.
• Coordinate security-control implementation and documentation with system owners, ISSOs/ISSMs, Systems Engineers, Network Engineers, Cloud Engineers, and Systems Administrators.
• Collect, review, organize, and validate technical evidence supporting security-control implementation and assessment.
• Track security-control deficiencies and support development and maintenance of Plans of Action and Milestones (POA&Ms).
• Monitor POA&M corrective actions and coordinate with responsible technical personnel to obtain evidence of remediation and closure.
• Support RMF control assessments, security reviews, validation activities, and authorization decisions.
• Review DISA STIG, vulnerability, configuration, and cybersecurity assessment results for inclusion in authorization documentation.
• Assist technical teams with interpreting RMF documentation and evidence requirements.
• Support continuous monitoring activities to maintain system authorization and cybersecurity compliance.
• Evaluate proposed system changes to determine potential impacts to authorization boundaries, security controls, and existing ATOs.
• Maintain accurate system inventories, authorization boundaries, architecture information, control documentation, and supporting artifacts.
• Coordinate authorization activities with Government cybersecurity personnel and other applicable USMC/DoD stakeholders.
• Track RMF milestones, deliverables, assessment findings, authorization expiration dates, and other compliance requirements.
• Support recurring cybersecurity reviews and provide RMF/ATO status information for program and Government briefings.
• Assist with development and delivery of RMF-related training and guidance to technical and program personnel.
• Support reauthorization activities, system modifications, technology refreshes, migrations, and system decommissioning as required.
Minimum Experience:
• Must have 5–8+ years of cybersecurity, information assurance, RMF, ATO, or security-compliance experience.
• Must have an active DoD Secret security clearance.
• Must satisfy applicable DoD 8140/DCWF requirements for Work Role 722 at the Advanced proficiency level.
• Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or related discipline.
• Hands-on experience supporting the DoD Risk Management Framework and system authorization processes.
• Experience developing and maintaining RMF/ATO documentation and supporting artifacts.
• Demonstrated experience using eMASS.
• Experience with security-control implementation, assessment, documentation, and evidence collection.
• Experience developing and managing POA&Ms and tracking cybersecurity findings through remediation.
• Working knowledge of DoD cybersecurity policies and authorization processes.
• Knowledge of NIST security controls, DISA STIGs, vulnerability-management processes, and continuous monitoring.
• Ability to interpret technical cybersecurity findings and translate them into appropriate RMF documentation.
• Experience coordinating with ISSOs, ISSMs, system owners, engineers, administrators, and Government cybersecurity personnel.
• Strong analytical, organizational, documentation, and communication skills.
Preferred Qualifications:
• CISSP, CAP/CGRC, SecurityX/CASP+, Security+, or other certification appropriate to the assigned DCWF work role.
• Extensive experience with eMASS and DoD RMF authorization packages.
• Experience supporting USMC or Department of the Navy RMF processes.
• Experience with NIST SP 800-53 security controls.
• Familiarity with ACAS/Tenable vulnerability results and DISA STIG compliance.
• Experience supporting cloud or hybrid environments, including Microsoft Azure.
• Experience with Microsoft 365 security/compliance environments.
• Previous USMC, Navy, DISA, or other DoD RMF/ATO experience.
Job Types: Full-Time
Salary: Based on experience
Schedule: Monday-Friday
Benefits:
• 401(k) matching
• Dental insurance
• Health insurance
• Paid time off
• Professional development assistance
• Vision insurance
STEELGATE LLC is a Service-Disabled, Veteran-Owned Small Business (SDVOSB) that prides itself in hiring top-level Subject Matter Experts (SME’s) proven to exceed deliverable expectations. STEELGATE LLC is focused on solving the hard problems facing our government and commercial clients. Our success lies in blending together relevant domain/functional knowledge with deep expertise in Information Technology, Cybersecurity, Defensive Cyber Operations, cloud-based DevSecOps, Data Analytics & AI, Acquisition and Acquisition Management, and more. STEELGATE LLC has a positive, inclusive workplace environment where all team members and partners work towards mutual success. We have established a reliable reach-back program whereas all SMEs are available to support, advise and directly complete mission deliverables when necessary. STEELGATE LLC has a worldwide reputation as a valued and trustworthy partner. Our can-do attitude and willingness to support any mission requirement sets us apart from other small business organizations. Find out more about STEELGATE LLC @ www.steelgatellc.com.
We are an equal opportunity employer, and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, protected veteran status, or any other characteristic protected by law.
group id: 91133289